Dynamic Traffic Mirroring for Application Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network systems lack comprehensive and integrated control mechanisms to manage access and usage across all users and devices, especially in BYOD and Cloud Computing environments, where traditional methods fail to identify and enforce policies effectively due to the rapid proliferation of applications and encrypted traffic.

Innovation Solution

The implementation of an application identification function with a dynamic traffic mirroring system that uses a combination of signature-based and heuristic processing, along with a scoring system, to accurately fingerprint applications and enforce policies dynamically, allowing for selective traffic mirroring and policy-based control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network control mechanisms are used, then device complexity is reduced, but network manageability and security control deteriorate in BYOD and Cloud environments

Engineering Contradiction:
Improvenetwork security controlVSAvoidcontrol mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network broker as an intermediary component that mediates between network policies and network traffic. The broker receives policy definitions from policy servers and dynamically enforces them by monitoring and controlling network flows, applications, and devices. This intermediary approach enables comprehensive security control without requiring complex reconfiguration of existing network infrastructure, as the broker operates as a standalone enforcement point that translates high-level policies into actionable network controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the network broker continuously monitors network traffic and policy compliance, then adjusts enforcement actions accordingly. The broker receives feedback from network devices about current traffic patterns and policy violations, and dynamically modifies network flows to maintain security requirements. This closed-loop feedback approach enables adaptive security control that responds to changing network conditions without manual intervention.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive traffic monitoring is implemented, then application identification accuracy improves, but loss of network bandwidth increases

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent implements selective traffic mirroring that copies only specific portions of network traffic based on policy requirements and risk levels. Rather than monitoring all traffic equally, the system applies partial monitoring to high-priority flows (e.g., new devices, untrusted networks, sensitive applications) while reducing or eliminating monitoring of low-priority traffic. This partial action approach maintains high identification accuracy for critical flows while minimizing overall bandwidth consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system applies different monitoring intensities and methods to different parts of the network traffic based on local characteristics. High-value traffic flows receive comprehensive inspection with deep packet analysis, while routine traffic receives lighter monitoring. The network broker dynamically adjusts monitoring quality based on device trust levels, application types, and network segments, enabling precise application identification where needed while conserving bandwidth in other areas.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If dynamic policy enforcement is implemented, then network manageability improves, but device complexity increases

Engineering Contradiction:
Improvenetwork manageabilityVSAvoidpolicy enforcement mechanism complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the policy enforcement functionality into distinct modular components: policy servers that define rules, network brokers that enforce rules, and policy agents on network devices that report status. This segmentation allows complex dynamic policy enforcement to be distributed across multiple simple components rather than concentrated in one complex system. Each component has a specific, well-defined function, making the overall system easier to manage and maintain despite its capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network broker is designed as a universal enforcement point that can handle multiple policy types, traffic control mechanisms, and device types through a single interface. Rather than requiring separate enforcement mechanisms for different policy scenarios, the broker provides multi-functional policy enforcement that adapts to various network conditions and requirements. This universality simplifies management by providing a single point of control for diverse policy enforcement needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10735511B2Device and related method for dynamic traffic mirroring
Publication Date: 2020.08.04 EXTREME NETWORKS INC
  • US10735511B2 patent drawing
  • US10735511B2 patent drawing
  • US10735511B2 patent drawing

AI summary

A function is provided in a network system for the dynamic mirroring of network traffic for a variety of purposes including the identification of characteristics of the traffic. Multiple criteria are established for when, what and where to mirror the traffic. The criteria include what frames of traffic to mirror, what portions of the selected frames to mirror, one or more portals through which to minor the selected frames, a destination for the mirroring and the establishment of a mirror in a device to carry out the mirroring. The criteria may also include when to stop the mirroring. The mirroring instructions can be changed based on the detection of a triggering event, such as authentication, device type or status, ownership of an attached function attached to the device, flow status, but not limited to that. The function may be established in one or more devices of the network.